The images in this article were generated with artificial intelligence. How we publish
A recent analysis of the sandboxing platform ANY.RUN He revealed a sophisticated operation that turned more than twenty Brazilian government sites into malware delivery channels. Far from being a simple mass phishing, the attackers took advantage of legitimate links and mailboxes to validate reliable logic and thus slide a malicious installer that then loads a modular backdoor built on modern technologies such as Electron and Node.js.
The initial vector was a luring that imitated official communications - police offices, digital procures and documents with QR codes - and in many cases the mail came from committed accounts passing the SPF, DKIM and DMARC checks. This combination of official appearance and redirection routes through compromised .gov.br domains drastically reduced the suspicions of both users and automatic controls, allowing the legitimate but patched installer to run an index.js with the ability to persevere and deliver subsequent payloads.

From the technical point of view, the most relevant thing was not just a download but a modular architecture: a backdoor written to evaluate and run JavaScript by eval (), create persistent machine identifiers, question commands at regular intervals and launch other malware - stealers, loaders, remote management tools - as appropriate to the operator. This design allows to change the subsequent damage without altering the first chain of infection, which complicates signature-based detection and containment after an initial infection.
The implications for banks and public entities are profound: confidence in a .gov.br URL or an authenticated mail no longer guarantees security. A compromised point can serve as a trampoline for the theft of credentials, side movements, financial fraud and exfiltration of sensitive data. In addition, the use of legitimate infrastructure fragments signals and reduces the visibility of security equipment, which can receive dispersed alerts rather than a clear pattern.
To reduce operational risk, security teams must complement traditional defences with behavior detections and threat hunting focused on the entire chain. It is critical to monitor installer loads and binary to detect modifications, correlate sandboxing sessions and web access records, and look for JavaScript performance indicators in unexpected contexts (e.g., electron apps that load external index.js). EDR solutions and threat hunting processes should prioritize process telemetry, called to eval () in JavaScript runtimes and outgoing connections to rotary infrastructure.
In the area of mail and prevention, in addition to maintaining SPF / DKIM / DMARC properly implemented, it is necessary to monitor the legitimate, delegable use of domains and have a secure corporate channel to validate critical communications. Organizations should enable simple and anonymous reports for employees to send suspicious messages, and response teams should analyse those reports beyond the initial verdict of a gateway, including inspection of links and intermediate readdresses.
At the containment and incident response level, act on early signals: isolate endpoints with unverified installers, revoke account credentials with unusual activity, force passwords and sessions rotation, and apply minimum access controls. The identification of government hosts engaged in the chain should be communicated to national authorities and response teams for coordinated mediation and blockade actions.

Specific technical recommendations should include application of white software lists, standard user-based execution block, monitoring of the integrity of common applications (especially Electron customers and their packages), and network rules for detecting beaconing patterns and unusual downloads. It is also essential that the teams maintain playbooks to respond to commitments that include the remediation of JavaScript back doors and the forensic evaluation of hidden persistences.
To deepen tactics and techniques related to phishing and persistence campaigns, see public resources that help map these threats, such as MITRE's ATT & CK matrix in phishing https: / / attack.mitre.org / techniques / T1566 / and national response teams such as CERT.br which facilitate coordination and reporting when public infrastructure is abused. In addition, ANY.RUN's interactive analysis report provides technical details and IoC that teams can use as a starting point for their hunting.
In conclusion, the campaign shows that adversaries gain advantage by combining highly credible social engineering with abuse of reliable infrastructure and modular backdoors. Effective defence requires full-cycle visibility, human validation of sensitive communications and rapid and coordinated response capacities both within the organisations concerned and with the entities responsible for protecting the public digital ecosystem.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...